PluginProbe
Yoast SEO – Advanced SEO with real-time guidance and built-in AI / trunk
Yoast SEO – Advanced SEO with real-time guidance and built-in AI vtrunk
28.5 28.4 28.3 28.2 28.1 28.0 27.9 27.8 27.7 27.6 27.5 trunk 18.0 18.1 18.2 18.3 18.4 18.4.1 18.5 18.5.1 18.6 18.7 18.8 18.9 19.0 All 129 releases
← All changes | src/config/wincher-client.php +9 -14 18.5 → trunk View file →
@@ -19,14 +19,14 @@
19 19
20 20 /**
21 21 * The option's key.
22 22 */
23 - const TOKEN_OPTION = 'wincher_tokens';
23 + public const TOKEN_OPTION = 'wincher_tokens';
24 24
25 25 /**
26 26 * Name of the temporary PKCE cookie.
27 27 */
28 - const PKCE_COOKIE_NAME = 'yoast_wincher_pkce';
28 + public const PKCE_TRANSIENT_NAME = 'yoast_wincher_pkce';
29 29
30 30 /**
31 31 * The WP_Remote_Handler instance.
32 32 *
@@ -41,13 +41,9 @@
41 41 * @param WP_Remote_Handler $wp_remote_handler The request handler.
42 42 *
43 43 * @throws Empty_Property_Exception Exception thrown if a token property is empty.
44 44 */
45 - public function __construct(
46 - Options_Helper $options_helper,
47 - WP_Remote_Handler $wp_remote_handler
48 - ) {
49 -
45 + public function __construct( Options_Helper $options_helper, WP_Remote_Handler $wp_remote_handler ) {
50 46 $provider = new Wincher_PKCE_Provider(
51 47 [
52 48 'clientId' => 'yoast',
53 49 'redirectUri' => 'https://auth.wincher.com/yoast/setup',
@@ -59,15 +55,15 @@
59 55 'pkceMethod' => 'S256',
60 56 ],
61 57 [
62 58 'httpClient' => new Client( [ 'handler' => $wp_remote_handler ] ),
63 - ]
59 + ],
64 60 );
65 61
66 62 parent::__construct(
67 63 self::TOKEN_OPTION,
68 64 $provider,
69 - $options_helper
65 + $options_helper,
70 66 );
71 67 }
72 68
73 69 /**
@@ -80,17 +76,16 @@
80 76
81 77 $url = $this->provider->getAuthorizationUrl(
82 78 [
83 79 'state' => WPSEO_Utils::format_json_encode( [ 'domain' => $parsed_site_url['host'] ] ),
84 - ]
80 + ],
85 81 );
86 82
87 83 $pkce_code = $this->provider->getPkceCode();
88 84
89 - // Store a session cookie with the PKCE code that we need in order to
85 + // Store a transient value with the PKCE code that we need in order to
90 86 // exchange the returned code for a token after authorization.
91 - $secure = ! empty( $_SERVER['HTTPS'] );
92 - \setcookie( self::PKCE_COOKIE_NAME, $pkce_code, 0, '/', '', $secure, true );
87 + \set_transient( self::PKCE_TRANSIENT_NAME, $pkce_code, \DAY_IN_SECONDS );
93 88
94 89 return $url;
95 90 }
96 91
@@ -103,9 +98,9 @@
103 98 *
104 99 * @throws Authentication_Failed_Exception Exception thrown if authentication has failed.
105 100 */
106 101 public function request_tokens( $code ) {
107 - $pkce_code = ! empty( $_COOKIE[ self::PKCE_COOKIE_NAME ] ) ? \sanitize_text_field( \wp_unslash( $_COOKIE[ self::PKCE_COOKIE_NAME ] ) ) : null;
102 + $pkce_code = \get_transient( self::PKCE_TRANSIENT_NAME );
108 103 if ( $pkce_code ) {
109 104 $this->provider->setPkceCode( $pkce_code );
110 105 }
111 106 return parent::request_tokens( $code );